Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

com.tariffmonkee/mcp

REMOTE · TARIFFMONKEE.COM · SCANNED SEP 26

Content, research, trust checks. Taiwan-specific: work permits, tax, property, fraud, localization.

Available components

+3 this week 74 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security57
Transport & Reachability100
Schema Quality & AI Usability78
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 2355 tokens (~123/item across 19 items; 19 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management67
  • Stability observed for 20 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 19 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the com.tariffmonkee/mcp server?

com.tariffmonkee/mcp is a hosted endpoint at https://tariffmonkee.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · tariffmonkee.com

# add to Claude Code
claude mcp add --transport http com-tariffmonkee-mcp 'https://tariffmonkee.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-tariffmonkee-mcp": {
      "url": "https://tariffmonkee.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-tariffmonkee-mcp": {
      "type": "http",
      "url": "https://tariffmonkee.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-tariffmonkee-mcp]
url = "https://tariffmonkee.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-tariffmonkee-mcp": {
      "type": "remote",
      "url": "https://tariffmonkee.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-tariffmonkee-mcp --url 'https://tariffmonkee.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-tariffmonkee-mcp:
    url: "https://tariffmonkee.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-tariffmonkee-mcp": {
      "Transport": "http",
      "Url": "https://tariffmonkee.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add com-tariffmonkee-mcp -t streamable-http -u 'https://tariffmonkee.com/mcp'
// mcp.json
{
  "mcpServers": {
    "com-tariffmonkee-mcp": {
      "type": "http",
      "url": "https://tariffmonkee.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 25 Sept 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 23 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.

  • 21 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 47 to 50. That category is still filling its 30-day observation window: 14 days of observed history at the previous scan, 15 at this one. The score rises as the window fills, whether or not the server changes.

  • 19 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 40 to 43. That category is still filling its 30-day observation window: 12 days of observed history at the previous scan, 13 at this one. The score rises as the window fills, whether or not the server changes.

  • 17 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

  • 14 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 12 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

  • 10 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 26 Sept 2026 · Probed https://tariffmonkee.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=tariffmonkee.com CN=WE1,O=Google Trust Services,C=US 6 Sept 2026 5 Dec 2026 ECDSA 256 ECDSA-SHA256 730149aba92d957f131addf453e225e7
SANs: tariffmonkee.com, www.tariffmonkee.com, *.www.tariffmonkee.com
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of tariffmonkee.com. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
tariffmonkee.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://tariffmonkee.com/mcp Verified 200
http (plaintext) http://tariffmonkee.com/mcp HTTPS enforced 301 https://tariffmonkee.com/mcp
MCP tools · 19 exposed · ~2,355 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
tariffmonkee-aeo-audit ~96

URL -> AI-readiness report. Checks schema.org structured data, crawlability (robots.txt, meta robots, canonical), and llms.txt presence, then returns a 0-100 score with specific recommendations for what's missing. Results are cached for 24 hours per URL. Costs $0.031 per call via x402.

NameTypeReqDescription
urlstringyesAbsolute http(s) URL of the page to audit.

No output schema declared.

No examples provided.

tariffmonkee-ai-visibility ~122

Business/domain + query -> does it appear in AI answers. Sends the real query to a live AI model with web search enabled and checks the actual response for a mention of the business and a citation linking to the domain. Costs $0.031 per call via x402.

NameTypeReqDescription
businessstringyesBusiness name to check for a mention.
domainstring–Optional. Domain to check for a citation, in addition to a name mention.
querystringyesThe question to ask the AI model. Max 500 characters.

No output schema declared.

No examples provided.

tariffmonkee-content ~84

Fetch a URL with a real rendered browser (JavaScript executed) and return clean Markdown. Results are cached for 24 hours per URL, so repeat calls for the same page are fast and don't re-render. Costs $0.005 per call via x402.

NameTypeReqDescription
urlstringyesAbsolute http(s) URL of the page to fetch and convert to Markdown.

No output schema declared.

No examples provided.

tariffmonkee-domain-intel ~88

Domain -> ownership and registration intelligence via RDAP. Returns registration age, registrar, privacy-proxy status, expiration date, nameservers, and detected mail provider. For technical configuration grading use /sitegrade; for URL-specific reputation use /linkcheck. Costs $0.021 per call via x402.

NameTypeReqDescription
domainstringyesBare domain to look up, no scheme.

No output schema declared.

No examples provided.

tariffmonkee-email-verify ~77

Email address -> deliverability verdict. Checks syntax, MX record presence, disposable/temp-mail domain match, and SPF/DMARC presence on the domain. Scoped to a single address, not a full domain security audit. Costs $0.003 per call via x402.

NameTypeReqDescription
emailstringyesEmail address to verify.

No output schema declared.

No examples provided.

tariffmonkee-extract ~110

Extract structured data from content you already have (e.g. from a prior /content call), using AI. No browser render involved -- pure AI extraction, cheaper and faster than fetching a URL fresh. Use this when you already have the text; use /extract-url if you only have a URL. Costs $0.016 per call via x402.

NameTypeReqDescription
contentstringyesRaw text content to extract data from.
schemaobjectyesJSON Schema describing the desired output structure.

No output schema declared.

No examples provided.

tariffmonkee-extract-url ~137

Fetch a URL with a real rendered browser and extract structured data from it in one call, using AI (tries multiple models in sequence for reliability). Use this when you don't already have the page content; use the cheaper /extract if you do. Results are cached for 24 hours per URL+schema combination. Costs $0.021 per call via x402.

NameTypeReqDescription
promptstring–Optional natural-language guidance on what to extract and where it appears.
schemaobjectyesJSON Schema describing the desired output structure.
urlstringyesAbsolute http(s) URL of the page to extract data from.

No output schema declared.

No examples provided.

tariffmonkee-gbp-audit ~107

Business -> visibility score, missing fields, review health, AI-readiness flags, fix list. Audits a Google Business Profile via DataForSEO's Business Data API: category, contact info, hours, claimed status, photos, and review rating/distribution. Costs $0.05 per call via x402.

NameTypeReqDescription
businessstringyesName of the business to audit.
locationstringyesFull location string, format: City,Region,Country.

No output schema declared.

No examples provided.

tariffmonkee-lead-discovery ~139

Discover and qualify local business leads by category and area -- no pre-existing list required. Searches Google Maps for the given category in the given area, then returns only businesses with at least one real red flag (unclaimed listing, missing photos, missing hours, missing website, low rating, or few reviews), as a CSV ready for cold outreach. Up to 10 qualified leads per call. Costs $0.75 per call via x402.

NameTypeReqDescription
areastringyesArea to search in, matching Google's own location format.
categorystringyesBusiness category to search for, matching a normal Google Maps search term.

No output schema declared.

No examples provided.

tariffmonkee-lead-list ~138

Audit-qualified lead list for prospecting. Submit up to 10 candidate local businesses; each is checked against its Google Business Profile (claimed status, photos, hours, website, description, rating, review count) and only businesses with at least one real red flag are returned, as a CSV ready to use as a cold-outreach list. Cheaper per-business than calling /gbp-audit individually if you use the full batch. Costs $0.60 per call via x402.

NameTypeReqDescription
businesses–yesArray of up to 10 objects, each { business, location }, matching Google Business Profile's own name/location format.

No output schema declared.

No examples provided.

tariffmonkee-linkcheck ~107

URL -> safety verdict. Checks the redirect chain, detects homograph/punycode hostname tricks, and cross-references the destination host against the URLhaus threat feed. Use to vet a single URL before fetching, sharing, or acting on it. For a full domain configuration grade use /sitegrade; for ownership/registration facts use /domain-intel. Costs $0.005 per call via x402.

NameTypeReqDescription
urlstringyesAbsolute http(s) URL to check.

No output schema declared.

No examples provided.

tariffmonkee-pdf ~105

Fetch a URL with a real rendered browser (JavaScript executed) and return a PDF of the full page. Not JSON -- the response body is the file itself. Results are cached for 24 hours per URL. Cache status and fetch time are reported in the X-Cached and X-Fetched-At response headers. Costs $0.01 per call via x402.

NameTypeReqDescription
urlstringyesAbsolute http(s) URL of the page to convert to PDF.

No output schema declared.

No examples provided.

tariffmonkee-research ~210

query -> up to 10 deduped, rendered sources as one token-budgeted bundle (~8,000 tokens combined). Combines /search (three-provider failover, region=tw Taiwan lane) with /content's rendered-page fetching internally, so you get one call instead of assembling search-then-fetch yourself. Sources are deduped by domain. Requires at least 3 successfully fetched sources to succeed -- returns sources_requested and sources_returned so you can see how many of the candidate set actually came back. Costs $0.031 per call via x402 -- only charged when a real search actually runs. A vague query pauses and asks for clarification at no cost; a search that can't find enough sources also pauses at no cost, suggesting a broadened query you can choose to run (which then does cost $0.031).

NameTypeReqDescription
querystringyesResearch query.
regionstring–Optional. Set to 'tw' for Traditional Chinese / Taiwan-region sources.

No output schema declared.

No examples provided.

tariffmonkee-screenshot ~104

Fetch a URL with a real rendered browser (JavaScript executed) and return a PNG screenshot of the full page. Not JSON -- the response body is the image itself. Results are cached for 24 hours per URL. Cache status and fetch time are reported in the X-Cached and X-Fetched-At response headers. Costs $0.01 per call via x402.

NameTypeReqDescription
urlstringyesAbsolute http(s) URL of the page to screenshot.

No output schema declared.

No examples provided.

tariffmonkee-search ~130

query -> structured search results (title, url, snippet), up to 10 per call. Backed by three providers with automatic failover (DataForSEO primary, Tavily and Serper as fallback) so a single provider outage doesn't take the endpoint down. Pass region=tw for a Traditional Chinese / Taiwan-region search lane. Results are cached for 24 hours per query+region. Costs $0.005 per call via x402.

NameTypeReqDescription
querystringyesSearch query.
regionstring–Optional. Set to 'tw' for Traditional Chinese / Taiwan-region results.

No output schema declared.

No examples provided.

tariffmonkee-serp-check ~107

Keyword + domain -> search position. Checks whether and where a domain ranks in Google organic results for a given keyword, via the same DataForSEO SERP data already powering /search. Costs $0.021 per call via x402.

NameTypeReqDescription
domainstringyesDomain to check the ranking of.
keywordstringyesSearch keyword to check rankings for.
regionstring–Optional. Set to 'tw' for Traditional Chinese / Taiwan-region results.

No output schema declared.

No examples provided.

tariffmonkee-sitegrade ~129

Domain -> security letter grade (0-100, A-F) from HTTPS reachability, security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy), and CAA records. Reports HTTPS connect success/failure, not raw cert expiry -- Workers can't read a remote server's cert metadata directly. For registration facts use /domain-intel; for URL reputation use /linkcheck. Costs $0.05 per call via x402.

NameTypeReqDescription
domainstringyesBare domain to grade, no scheme.

No output schema declared.

No examples provided.

tariffmonkee-trust-audit ~164

Orchestrated bundle: runs /linkcheck, /sitegrade, and /domain-intel (plus /email-verify if an email is supplied) and synthesizes one confidence-weighted trust verdict, explicitly flagging disagreement between sources -- e.g. a very new domain paired with an unusually mature TLS/header setup -- rather than just concatenating four outputs. Supply at least one of domain, url, or email. Costs $0.10 per call via x402.

NameTypeReqDescription
domainstring–Domain to audit. Required if url and email are both omitted.
emailstring–Email address to audit. Optional in addition to domain/url.
urlstring–URL to audit. Required if domain and email are both omitted.

No output schema declared.

No examples provided.

tariffmonkee-visibility-report ~201

White-label local visibility report for one business -- combines Google Business Profile completeness, organic search ranking for a target keyword, and AI answer-engine visibility for a buyer-intent query into a single PDF deliverable. White-label by design: no TariffMonkee branding anywhere in the report output, so agencies can present it under their own name to a client or prospect. Costs $0.15 per call via x402.

NameTypeReqDescription
businessstringyesExact business name to audit.
domainstringyesThe business's own website domain, used for the search-ranking and AI-citation checks.
keywordstringyesSearch keyword to check this business's organic ranking for.
locationstringyesCity, region, and country of the business, matching Google Business Profile's own location format.
querystringyesBuyer-intent question to check whether an AI model mentions this business when answering. Max 500 characters.

No output schema declared.

No examples provided.

Common questions

What is the com.tariffmonkee/mcp server?

com.tariffmonkee/mcp is listed in the public MCP registry as com.tariffmonkee/mcp. Content, research, trust checks. Taiwan-specific: work permits, tax, property, fraud, localization. This page covers its hosted endpoint (https://tariffmonkee.com/mcp).

Is the com.tariffmonkee/mcp server safe to use?

com.tariffmonkee/mcp scores 74 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the com.tariffmonkee/mcp server expose?

com.tariffmonkee/mcp exposes 19 tools: tariffmonkee-content, tariffmonkee-extract, tariffmonkee-extract-url, tariffmonkee-aeo-audit, tariffmonkee-search, and 14 more. Their descriptions and schemas cost roughly 2,355 tokens of context every time the server is loaded.

Does the com.tariffmonkee/mcp server require authentication?

No. We connected to com.tariffmonkee/mcp without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the com.tariffmonkee/mcp server still maintained?

com.tariffmonkee/mcp is still listed as active in the MCP registry. We last reached this channel on 26 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.