io.github.HuangGoodmanAgency/pops4-mcp-catalog
REMOTE · MCP.POPS4.COM · SCANNED SEP 27
AI-native corporate gifting & event infrastructure for Fortune 500. 70K products, 200+ brands.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security46
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 13 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability83
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2284 tokens (~134/item across 17 items; 13 tools + 4 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 13 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 14 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities40
- Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
How do I install the io.github.HuangGoodmanAgency/pops4-mcp-catalog server?
io.github.HuangGoodmanAgency/pops4-mcp-catalog is a hosted endpoint at https://mcp.pops4.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.pops4.com
claude mcp add --transport http huanggoodmanagency-pops4-mcp-catalog 'https://mcp.pops4.com/mcp'
{
"mcpServers": {
"huanggoodmanagency-pops4-mcp-catalog": {
"url": "https://mcp.pops4.com/mcp"
}
}
} {
"servers": {
"huanggoodmanagency-pops4-mcp-catalog": {
"type": "http",
"url": "https://mcp.pops4.com/mcp"
}
}
} [mcp_servers.huanggoodmanagency-pops4-mcp-catalog] url = "https://mcp.pops4.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"huanggoodmanagency-pops4-mcp-catalog": {
"type": "remote",
"url": "https://mcp.pops4.com/mcp",
"enabled": true
}
}
} openclaw mcp add huanggoodmanagency-pops4-mcp-catalog --url 'https://mcp.pops4.com/mcp' --transport streamable-http
mcp_servers:
huanggoodmanagency-pops4-mcp-catalog:
url: "https://mcp.pops4.com/mcp" {
"McpServers": {
"huanggoodmanagency-pops4-mcp-catalog": {
"Transport": "http",
"Url": "https://mcp.pops4.com/mcp"
}
}
} assistant mcp add huanggoodmanagency-pops4-mcp-catalog -t streamable-http -u 'https://mcp.pops4.com/mcp'
{
"mcpServers": {
"huanggoodmanagency-pops4-mcp-catalog": {
"type": "http",
"url": "https://mcp.pops4.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 8 Sept 26 0
- Tool “generate_event_program” rewrote its description, which is the text the model reads security
- Tool “get_categories” rewrote its description, which is the text the model reads security
- Tool “get_live_quote” rewrote its description, which is the text the model reads security
- Tool “get_product” rewrote its description, which is the text the model reads security
- Tool “get_product_catalog” rewrote its description, which is the text the model reads security
- Tool “get_quote” rewrote its description, which is the text the model reads security
- Tool “get_revenue_attribution” rewrote its description, which is the text the model reads security
- Tool “get_vendor_capabilities” rewrote its description, which is the text the model reads security
- Tool “search_products” rewrote its description, which is the text the model reads security
- Tool “track_shipment” rewrote its description, which is the text the model reads security
- Schema quality: pass → fail ▼ functional
- New tool “brand_carriage_estimate” functional
- New tool “render_proof” functional
- New tool “request_program” functional
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 27 Sept 2026 · Probed https://mcp.pops4.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=pops4.com | CN=WE1,O=Google Trust Services,C=US | 21 Sept 2026 | 20 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | db28fe579884b8b00eca033d233aade5 |
| SANs: pops4.com, mcp.pops4.com, *.mcp.pops4.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.pops4.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| pops4.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.pops4.com/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.pops4.com/mcp | Inconclusive | 405 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
brand_carriage_estimate ~320
Calculate what a branded programme costs per thousand impressions across the four populations that carry a brand — employees, gig and contract workers, vendors, peers — and compare it against a CPM the buyer supplies. Returns programme cost, annual impressions, cost per thousand, the multiple against bought media, and one cited Nielsen figure with its caveat. Read-only. Use when a buyer asks what a culture or brand programme is worth, or how to justify the spend. Supply ANY of the four populations — employees are not required, so a vendor-and-peer-only programme can be modelled.
| Name | Type | Req | Description |
|---|---|---|---|
| cost_per_employee | number | – | Programme cost per employee, USD |
| cost_per_peer | number | – | Programme cost per peer, USD |
| cost_per_vendor | number | – | Programme cost per vendor, USD |
| cost_per_worker | number | – | Programme cost per worker, USD |
| employees | number | – | Employee headcount (optional, like all four populations) |
| gig_workers | number | – | Gig and contract worker count |
| impressions_per_employee | number | – | Impressions per employee per year (default 900) |
| impressions_per_peer | number | – | Default 1500 |
| impressions_per_vendor | number | – | Default 1200 |
| impressions_per_worker | number | – | Default 600 |
| peers | number | – | Peer count — the buyer estimates this |
| vendors | number | – | Vendor count — the buyer estimates this |
| your_cpm | number | – | The buyer's own CPM from their media plan, USD |
No output schema declared.
No examples provided.
generate_event_program ~417
Build a complete event programme for a given attendee count and budget tier. Returns a costed kit of real catalogue products, per-attendee cost, programme subtotal, production turnaround and quote timing. Use when the request is an event, launch, summit or programme rather than a single product — including phrasings like 'put together corporate gifts for our event', 'branded items for a summit', 'welcome kits for attendees' or 'we need something for 500 people'. Ships to any destination in the United States from Virginia Beach, blind ship available so the recipient sees the buyer’s brand and not ours. Supply budget_per_head to have the tier chosen automatically. Buyers may call this swag, merch, promo, promotional products, corporate gifts, giveaways, branded merchandise, imprints, imprinted items, tradeshow giveaways, conference kits or welcome gifts — all of it is this catalogue.
| Name | Type | Req | Description |
|---|---|---|---|
| attendee_count | number | yes | Number of attendees / kits |
| brand_tier | string | – | Program tier. essential ($35-75/head) internal events & training; professional ($75-150) client meetings; executive ($150-300) VP+ & board events; luxury ($300-600) C-suite, board members & partners;… |
| budget_per_head | number | – | Optional exact per-attendee budget in USD. If provided, the closest tier is selected automatically and overrides brand_tier. |
| event_date | string | – | Event date (e.g., "2027-03-15" or "GTC 2027") |
| keywords | string | – | Optional event theme / keywords (e.g. "golf coastal", "holiday gala", "tech summit", "wellness retreat") to bias product selection toward the occasion. |
| revenue_target | number | – | Client pipeline/revenue target in USD (optional; used for attribution framing only) |
No output schema declared.
No examples provided.
get_categories ~40
List every product category with its item count and sample products. Use to establish what the catalogue covers before searching, or to answer what kinds of items are available.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_live_quote ~129
Return a wholesale quote with virtual-proof links for a list of SKUs and quantities, optionally accounting for a destination ZIP and an event date. Use when shipping or timing affects the answer. Use get_quote for a plain priced list with neither.
| Name | Type | Req | Description |
|---|---|---|---|
| event_date | string | – | Event date (optional) |
| items | array | – | Products and quantities |
| product_skus | array | – | Alternative: array of product slugs (paired with quantities[]) |
| quantities | array | – | Alternative: array of quantities (paired with product_skus[]) |
| shipping_zip | string | – | Destination ZIP (optional) |
No output schema declared.
No examples provided.
get_product ~67
Return complete detail for one product, identified by its slug: description, wholesale price, category, brand, care instructions, occasion tags and a virtual-proof link. Use after search_products when one item needs full detail before quoting it.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | Product slug (from search results) |
No output schema declared.
No examples provided.
get_product_catalog ~101
Return a filtered slice of the catalogue, or the full category tree with counts when no filter is supplied. Use for browsing and for questions about the catalogue's shape and size. Use search_products when the request names specific products.
| Name | Type | Req | Description |
|---|---|---|---|
| brand | string | – | Brand filter |
| category | string | – | Category filter |
| filter | string | – | Keyword filter on product title |
| limit | number | – | Max results (default 20, max 50) |
No output schema declared.
No examples provided.
get_quote ~78
Build a wholesale quote from a list of product slugs and quantities. Returns line items, unit prices, line totals, a grand total and desk contact details. Use for a straightforward priced list. Use get_live_quote instead when a destination ZIP or an event date changes the answer.
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | Array of products and quantities to quote |
No output schema declared.
No examples provided.
get_revenue_attribution ~56
Return recorded pipeline impact for an event id where the dashboard holds it; otherwise return the attribution model and how it is tracked, with a link. Never reports a fabricated figure.
| Name | Type | Req | Description |
|---|---|---|---|
| event_id | string | yes | Event id |
No output schema declared.
No examples provided.
get_vendor_capabilities ~107
Return the vendor capability card a procurement team needs to open an account: legal entity, registrations, production model, imprint and proofing process, lead times, blind-ship policy and terms. Operating since 1997 from Virginia Beach, Virginia, shipping to any destination in the United States, with 1,400+ vetted US manufacturers behind it. Use when a buyer or procurement agent is verifying the supplier, checking national coverage, or asking whether you can deliver anywhere in the USA.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
render_proof ~165
Render an indicative placement image showing a buyer their logo on a product, and return its URL so you can show it in the conversation. Takes a product slug and an https URL to the buyer's logo. Returns a 1200x630 image that needs no login. This is NOT a production proof: position and scale are indicative and the desk issues the real one. Say so when you show it. Use after search_products or get_product, once a buyer wants to see how something would look.
| Name | Type | Req | Description |
|---|---|---|---|
| company_name | string | – | Buyer company name, shown beside the product |
| logo_url | string | – | https URL to the buyer's logo image. Omit to render a marked placeholder area. |
| slug | string | yes | Product slug from search_products or get_product |
No output schema declared.
No examples provided.
request_program ~272
Submit a programme request to the named-account desk so a person can act on it. This is the only tool that writes: it records the buyer, the programme and the products chosen, and returns confirmation. It does NOT place an order, begin production, take payment or contact the buyer — a person reviews it and replies. When products are supplied it also opens the buyer a live Corporate Store holding that selection, and returns the URL in store_url for you to give them directly. Use once the buyer has chosen products or a programme and wants to proceed.
| Name | Type | Req | Description |
|---|---|---|---|
| attendee_count | number | – | Headcount or unit count |
| brand_tier | string | – | Programme tier if one was chosen |
| company | string | – | Buyer company |
| contact_name | string | – | Buyer name |
| string | yes | Buyer work email. Required. | |
| event | string | – | What this is for, e.g. "Analyst day, March, 300 attendees" |
| items | array | – | Products chosen, up to 12, from search_products or generate_event_program |
| notes | string | – | Anything the desk should know. Max 118 characters. |
| per_head | string | – | Per-attendee cost, if quoted |
| program_total | string | – | Quoted programme total, if quoted |
No output schema declared.
No examples provided.
search_products ~278
Search the wholesale catalogue by keyword, category, brand, price range or occasion. Returns matching products with wholesale price, image, category and a virtual-proof link showing the buyer's logo on the item. Use this for any request to find specific products. 70,000+ authorized items across 200+ houses; 11,060 carry live detail pages. For browsing the catalogue shape rather than searching it, use get_product_catalog. Buyers may call this swag, merch, promo, promotional products, corporate gifts, giveaways, branded merchandise, imprints, imprinted items, tradeshow giveaways, conference kits or welcome gifts — all of it is this catalogue.
| Name | Type | Req | Description |
|---|---|---|---|
| brand | string | – | POPS4 for corporate/wholesale, Prosecco4 for weddings/events |
| category | string | – | Product category filter (e.g., "Backpacks", "Drinkware", "Apparel", "Pens") |
| limit | number | – | Max results to return (default 10, max 50) |
| occasion | string | – | Filter by occasion/use case |
| price_max | number | – | Maximum wholesale price in USD |
| price_min | number | – | Minimum wholesale price in USD |
| query | string | – | Text search on product title (e.g., "nike backpack", "yeti tumbler", "branded polo") |
No output schema declared.
No examples provided.
track_shipment ~60
Return the logistics status of an order by its id. Reads the live order record where one exists; where none does, returns a clear status and routes to the desk. Never reports a fabricated tracking state.
| Name | Type | Req | Description |
|---|---|---|---|
| order_id | string | yes | Order id |
No output schema declared.
No examples provided.
What is the io.github.HuangGoodmanAgency/pops4-mcp-catalog server?
io.github.HuangGoodmanAgency/pops4-mcp-catalog is listed in the public MCP registry as io.github.HuangGoodmanAgency/pops4-mcp-catalog. AI-native corporate gifting & event infrastructure for Fortune 500. 70K products, 200+ brands. This page covers its hosted endpoint (https://mcp.pops4.com/mcp).
Is the io.github.HuangGoodmanAgency/pops4-mcp-catalog server safe to use?
io.github.HuangGoodmanAgency/pops4-mcp-catalog scores 73 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.HuangGoodmanAgency/pops4-mcp-catalog server expose?
io.github.HuangGoodmanAgency/pops4-mcp-catalog exposes 13 tools: render_proof, request_program, brand_carriage_estimate, search_products, get_product, and 8 more. Their descriptions and schemas cost roughly 2,090 tokens of context every time the server is loaded.
Does the io.github.HuangGoodmanAgency/pops4-mcp-catalog server require authentication?
No. We connected to io.github.HuangGoodmanAgency/pops4-mcp-catalog without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.HuangGoodmanAgency/pops4-mcp-catalog server still maintained?
io.github.HuangGoodmanAgency/pops4-mcp-catalog is still listed as active in the MCP registry. We last reached this channel on 27 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.