# marocain.investments — {GIN} real-estate intelligence (Morocco) (npm · @marocain/mcp-server)

{GIN} verdict, M-Value AVM, market facts + semantic search for Moroccan real estate. Moat-safe.

- Trust score: 68/100 (medium)
- Change this week: +23
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- npm · `@marocain/mcp-server`: 68/100 (this document), [markdown](https://verifymcp.io/servers/hei33enberg-marocain-mcp-server/marocain-mcp-server.md), [page](https://verifymcp.io/servers/hei33enberg-marocain-mcp-server/marocain-mcp-server)

## Channel facts

- Registry: `npm`
- Package: `@marocain/mcp-server`
- Version: `0.1.9`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Supply Chain Security**: 83/100
  - No malware found by supply-chain analysis.
  - CVE check failed: a known medium-severity CVE affects @hono/node-server 1.19.17, reached via @modelcontextprotocol/sdk > @hono/node-server. A fixed version is available.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (94 of 98), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 24 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 74/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 1349 tokens (~122/item across 11 items; 11 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 27/100
  - Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add hei33enberg-marocain-mcp-server -- npx -y @marocain/mcp-server
```

### Codex

```bash
codex mcp add hei33enberg-marocain-mcp-server -- npx -y @marocain/mcp-server
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "hei33enberg-marocain-mcp-server": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@marocain/mcp-server"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add hei33enberg-marocain-mcp-server --command npx --arg -y --arg @marocain/mcp-server
```

### Hermes

```yaml
mcp_servers:
  hei33enberg-marocain-mcp-server:
    command: "npx"
    args: ["-y", "@marocain/mcp-server"]
```

### Other

```json
{
  "mcpServers": {
    "hei33enberg-marocain-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@marocain/mcp-server"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-03 (score 68, +4)

- [functional improvement] Stability: unverified → 0.27

### 2026-08-02 (score 64, +44)

- [security regression] GHSA-frvp-7c67-39w9 affects this package: medium
- [security regression] Known CVEs: unverified → fail
- [security regression] Provenance: unverified → fail
- [security improvement] Install scripts: unverified → pass
- [security improvement] Malware scan: unverified → pass
- [security] Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window).
- [functional regression] Security disclosure: fail → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional improvement] Schema quality: unverified → excellent
- [functional improvement] License: unverified → pass
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional] First check of Schema quality: unverified
- [functional] Licence: MIT

### 2026-07-31 (score 20, −25)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-27 (score 45)

First indexed and scored.

## MCP tools (11)

### `search_listings` (~158 tokens)

Search AI-graded Moroccan luxury listings by city, typology, price, rooms and a free-text query. Returns structured listings with prices and {GIN} scores. Never returns agent contact details.

Input parameters:

- `city` (string): City name, e.g. Marrakech, Casablanca, Tangier.
- `limit` (number): Max results (default 20, max 50).
- `max_price_usd` (number): Maximum asking price in USD.
- `min_price_usd` (number): Minimum asking price in USD.
- `min_rooms` (number): Minimum number of rooms.
- `q` (string): Free-text query.
- `typology` (string): Property type, e.g. villa, apartment, riad, land.

### `get_listing` (~65 tokens)

Full detail for one listing by id: price (USD/MAD), AI scores, M-Value AVM, FCR/title trust, source provenance and the {GIN} pillars + verdict. Never returns the agent's phone.

Input parameters:

- `id` (string, required): Listing id (UUID).

### `get_gin_score` (~74 tokens)

The {GIN} coherent verdict for a listing: the Quality pillar (asset, compute_marocain_score), the Deal pillar (price-vs-AVM + momentum) and the one fused buy/hold/pass verdict. The authored number an investor can defend.

Input parameters:

- `id` (string, required): Listing id (UUID).

### `get_market` (~69 tokens)

Macro market facts for a city or national scope — median price, supply, momentum and the catalysts (WC2030, TGV) the {GIN} Deal pillar is benchmarked against.

Input parameters:

- `scope` (string, required): City slug (e.g. marrakech) or 'morocco' for national.

### `listing_derive` (~75 tokens)

AI-derived investor narrative for a listing — a one-paragraph thesis synthesising the {GIN} pillars, financial vision and location into a single decision memo.

Input parameters:

- `lang` (string): Locale: en, fr, es, de, pl, ar (default en).
- `listing_id` (string, required): Listing id (UUID).

### `semantic_search` (~146 tokens)

Semantic / conceptual vector search across the Moroccan catalogue AND the authored guides (Foreign Buyer's Playbook, Morocco-vs-Dubai thesis, AI scoring methodology, residency, city theses). Use for fuzzy / lifestyle / thesis queries that don't map to exact filters — e.g. 'quiet authentic seaside neighbourhood with rental upside' or 'why Morocco over Dubai'. Returns ranked items with a similarity score. Never returns agent contact details.

Input parameters:

- `k` (number): Max results (default 8, max 20).
- `q` (string, required): Natural-language / conceptual query.
- `types` (string): Optional comma-separated doc kinds to search: listing, district, investment, knowledge, essay.

### `gin_ask` (~96 tokens)

Ask T{AI]GIN — the {GIN} agentic investment analyst — a one-shot natural-language question. It plans, searches the catalogue + authored guides, scores with the {GIN} pillars and answers grounded with citations. Use for open questions ('which Tangier district has the best rental upside?', 'why Morocco over Dubai?'). Never returns agent contact details.

Input parameters:

- `q` (string, required): Natural-language question for the analyst.

### `gin_deal_memo` (~86 tokens)

Generate a structured investor DEAL MEMO for one listing id: the {GIN} Quality + Deal verdict, M-Value AVM with value-vs-ask, gross yield, strengths, risks, district read and next steps. Honest (won't soften an overpriced verdict). Decision support, not a certified appraisal.

Input parameters:

- `listing_id` (string, required): Listing id (UUID).

### `request_service` (~215 tokens)

Submit a buyer ENQUIRY (or request a viewing / valuation / financing / renovation / legal help) for a listing. This is the ONLY conversion path: it routes the enquiry through marocain.investments to the listing's verified agent and returns a confirmation reference — it NEVER returns the agent's contact (the platform intermediates all contact). Works for listings that have a claimed, verified agent; for not-yet-claimed scraped listings it returns a clear note instead of routing. Requires the buyer's name + email so the agent can follow up.

Input parameters:

- `buyer_email` (string, required): The buyer's email for the agent to reply to.
- `buyer_name` (string, required): The enquiring buyer's name.
- `buyer_phone` (string): Optional buyer phone.
- `listing_id` (string, required): Listing id (UUID) to enquire about.
- `message` (string): Optional message — what they're looking for / questions.
- `service_interest` (string): Optional: viewing, valuation, financing, renovation, legal, etc.

### `list_services` (~126 tokens)

List the platform's transactable services + EUR prices — for BUYERS (AI staging, viral content, refundable reservation, bank-honored appraiser, on-site visitation, the €199 AI business-model plan, plus request-only lawyer / financing / bespoke commercialization) and for AGENTS/sellers (listing boost, photo relight). Returns each `product_type` + its `variant` ids + price, which `order_service` needs. NOTE: card checkout for instant products may be temporarily unavailable while the payment processor is being reconnected; request-based services and buyer enquiries work regardless.

### `order_service` (~239 tokens)

Place an order for any platform service (a `product_type` + `variant` from list_services). Instant products return a Stripe `checkout_url` to complete payment on-platform; request-only products (lawyer, financing, commercialization, contact) return a tracked `order_id` with no upfront charge. Requires the buyer's email. NEVER returns agent/seller contact. For a plain buyer enquiry to a listing's agent, prefer `request_service`.

Input parameters:

- `buyer_email` (string, required): Buyer's email (required).
- `buyer_name` (string): Buyer's name.
- `buyer_phone` (string): Optional buyer phone.
- `listing_id` (string): Listing id (UUID) the service applies to.
- `message` (string): Optional note / scope (request-only products).
- `product_type` (string, required): From list_services, e.g. staging, viral, reservation, appraiser, visaitation, commercialization_plan, lawyer, financing, listing_boost, photo_relight.
- `variant` (string, required): The variant id for that product (from list_services), e.g. single / pack / deposit / essential / standard / premier.

## Diagnostics

Captured diagnostic sections: Provenance, Vulnerabilities, Dependencies. The full working is on the page: https://verifymcp.io/servers/hei33enberg-marocain-mcp-server/marocain-mcp-server#diagnostics

## Score history

- 2026-08-03: 68
- 2026-08-02: 64
- 2026-08-01: 20
- 2026-07-31: 20
- 2026-07-30: 45
- 2026-07-28: 45
- 2026-07-27: 45

## Links

- npm package: https://www.npmjs.com/package/@marocain/mcp-server
- Socket report: https://socket.dev/npm/package/@marocain/mcp-server
- Repository: https://github.com/Hei33enberg/marocain-mcp-server
- Changelog RSS feed: https://verifymcp.io/servers/hei33enberg-marocain-mcp-server/marocain-mcp-server/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/hei33enberg-marocain-mcp-server/marocain-mcp-server/changelog.json
- HTML version of this page: https://verifymcp.io/servers/hei33enberg-marocain-mcp-server/marocain-mcp-server
